Skip to content

Malware

MISTPEN

According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable Executable (PE) files.

MISTPEN is a Windows malware family operated by UNC2970.

Background

Mandiant describes MISTPEN as a compact C-language backdoor whose core purpose is to fetch and run Portable Executable (PE) files. It is built by tampering with the open-source Notepad++ binhex plugin v2.0.0.1, adding to the DllMain function a thread that launches the malicious code.


Source: Malpedia (Fraunhofer FKIE).